iOS 26.5.2 Cropped Screenshot Bug Exposes Full Images, Potentially Leaking Sensitive Data
What Happened — A regression in iOS 26.5.2 causes screenshots that are cropped in the preview pane to be saved in their original, uncropped form. Users who rely on the quick‑crop workflow end up sharing the full screenshot, unintentionally revealing information they tried to hide.
Why It Matters for Compliance & Audit Readiness
- The bug creates a de‑facto data‑exposure incident, directly challenging privacy‑by‑design requirements in SOC 2 CC6 (Confidentiality) and GDPR/CCPA obligations.
- Continuous‑compliance programs must capture such platform‑level failures as evidence of control testing and remediation tracking.
- Verisq’s CookiePLUS Privacy capability provides automated consent logging and DSAR readiness reports that can serve as audit‑ready proof that you’ve identified and mitigated unintended data disclosures.
Who Is Affected — Consumer‑focused mobile app developers, enterprises that distribute internal iOS apps, and any organization that relies on iPhone screenshots to share sanitized information (e.g., support teams, legal, sales).
Recommended Actions
- Immediately verify that all screenshots are reviewed in the Photos app before distribution.
- Update internal SOPs to include a “post‑crop verification” step until Apple releases a fix.
- Map this bug to SOC 2 CC6 controls (Data Classification, Privacy Controls) and capture remediation evidence in your continuous‑compliance dashboard.
Source: ZDNet Security
Technical Notes
- Affected version: iOS 26.5.2 (and possibly early iOS 27 beta builds).
- No CVE assigned; the issue is a regression in the screenshot‑editing pipeline, not an exploitable vulnerability.
- Data type exposed: any visual content captured in a screenshot, including PII, proprietary UI, or confidential communications.